Zabbix: (Prototype pollution vulnerability in searchParamsToObject() is leading ...) (CVE-2026-23929)
A prototype pollution vulnerability exists in the searchParamsToObject() function of Zabbix. This vulnerability can lead to security issues by allowing an attacker to manipulate the prototype of a base object. The vulnerability affects multiple specific versions of Zabbix as listed. The severity is assessed as medium based on the available CVSS vector. No known exploits are reported in the wild. No official patch or remediation information is provided in the source data.
AI Analysis
Technical Summary
The vulnerability identified as CVE-2026-23929 involves prototype pollution in the searchParamsToObject() function within Zabbix. Prototype pollution vulnerabilities allow attackers to inject properties into JavaScript object prototypes, potentially leading to unexpected behavior or security issues. The CVSS 4.0 vector indicates network attack vector, low attack complexity, low privileges required, user interaction needed, and high impact on confidentiality, integrity, and availability. Multiple specific Zabbix package versions distributed in Ubuntu LTS releases are affected. There is no information on available patches or fixes in the provided data.
Potential Impact
Successful exploitation of this prototype pollution vulnerability could allow an attacker with low privileges and requiring user interaction to cause high impact on confidentiality, integrity, and availability of the affected system. However, no known exploits in the wild have been reported, and the vulnerability requires user interaction to be exploited.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or official fix information is provided, users should monitor vendor channels for updates. Until a fix is available, consider restricting access and user interactions that might trigger the vulnerable function.
Zabbix: (Prototype pollution vulnerability in searchParamsToObject() is leading ...) (CVE-2026-23929)
Description
A prototype pollution vulnerability exists in the searchParamsToObject() function of Zabbix. This vulnerability can lead to security issues by allowing an attacker to manipulate the prototype of a base object. The vulnerability affects multiple specific versions of Zabbix as listed. The severity is assessed as medium based on the available CVSS vector. No known exploits are reported in the wild. No official patch or remediation information is provided in the source data.
CVSS v4.0
Affected software
pkg:deb/ubuntu/zabbix?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/zabbix?arch=source&distro=esm-apps/xenialpkg:deb/ubuntu/zabbix?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/zabbix?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/zabbix?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/zabbix?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability identified as CVE-2026-23929 involves prototype pollution in the searchParamsToObject() function within Zabbix. Prototype pollution vulnerabilities allow attackers to inject properties into JavaScript object prototypes, potentially leading to unexpected behavior or security issues. The CVSS 4.0 vector indicates network attack vector, low attack complexity, low privileges required, user interaction needed, and high impact on confidentiality, integrity, and availability. Multiple specific Zabbix package versions distributed in Ubuntu LTS releases are affected. There is no information on available patches or fixes in the provided data.
Potential Impact
Successful exploitation of this prototype pollution vulnerability could allow an attacker with low privileges and requiring user interaction to cause high impact on confidentiality, integrity, and availability of the affected system. However, no known exploits in the wild have been reported, and the vulnerability requires user interaction to be exploited.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or official fix information is provided, users should monitor vendor channels for updates. Until a fix is available, consider restricting access and user interactions that might trigger the vulnerable function.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-23929
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 4.0
Threat ID: 6a870a6facd9273b49b589c9
Added to database: 08/20/2026, 14:08:47 UTC
Last enriched: 08/20/2026, 14:26:36 UTC
Last updated: 08/20/2026, 22:52:11 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.